创建Sabre Session Token时遇ICE安全系统521连接错误的解决方法
Sabre SessionCreateRQ 报错:Unable to connect to ICE security system : 521
问题描述
按照Sabre开发者指南创建Session Token,已成功生成无会话令牌,但使用Postman测试SessionCreateRQ请求时出现异常错误,已排除凭证问题。
请求内容
<soap-env:Envelope xmlns:soap-env="http://schemas.xmlsoap.org/soap/envelope/" xmlns:eb="http://www.ebxml.org/namespaces/messageHeader" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsd="http://www.w3.org/1999/XMLSchema"> <soap-env:Header> <eb:MessageHeader soap-env:mustUnderstand="1" eb:version="1.0"> <eb:ConversationId>c88f8e8cb699</eb:ConversationId> <eb:From> <eb:PartyId type="urn:x12.org:IO5:01">999999</eb:PartyId> </eb:From> <eb:To> <eb:PartyId type="urn:x12.org:IO5:01">123123</eb:PartyId> </eb:To> <eb:CPAId>XXXX</eb:CPAId> <eb:Service eb:type="OTA">SessionCreateRQ</eb:Service> <eb:Action>SessionCreateRQ</eb:Action> <eb:MessageData> <eb:MessageId>1000</eb:MessageId> <eb:Timestamp>2024-02-13T16:32:31Z</eb:Timestamp> <eb:TimeToLive>2024-02-13T16:32:31Z</eb:TimeToLive> </eb:MessageData> </eb:MessageHeader> <wsse:Security xmlns:wsse="http://schemas.xmlsoap.org/ws/2002/12/secext" xmlns:wsu="http://schemas.xmlsoap.org/ws/2002/12/utility"> <wsse:UsernameToken> <wsse:Username>9999</wsse:Username> <wsse:Password>XXXXXXX</wsse:Password> <Organization>XXXX</Organization> <Domain>DEFAULT</Domain> </wsse:UsernameToken> </wsse:Security> </soap-env:Header> <soap-env:Body> <sws:SessionCreateRQ xmlns:sws="http://webservices.sabre.com" Version="1.0.0"/> </soap-env:Body> </soap-env:Envelope>
错误响应
<soap-env:Body> <soap-env:Fault> <faultcode>soap-env:Server.SystemFailure</faultcode> <faultstring>Unable to connect to ICE security system : 521</faultstring> <detail> <StackTrace>com.sabre.universalservices.base.exception.ApplicationICEException: errors.authentication.USG_SECURITY_ICE_ERROR</StackTrace> </detail> </soap-env:Fault> </soap-env:Body>
错误成因
- ICE是Sabre的核心安全认证系统,错误码521本质是请求头中的关键配置字段与Sabre后台不匹配,或环境配置错误导致系统无法完成认证
- SessionCreateRQ对MessageHeader和Security头的字段一致性要求极高,哪怕字段值存在大小写、字符差异,或环境标识错误,都会触发该连接失败错误
解决办法
- 核对
eb:CPAId与Organization字段值:两者必须和Sabre提供的配置信息完全一致,不能有任何拼写或格式错误 - 检查
Domain字段:测试环境下部分场景需使用TEST而非DEFAULT,请确认当前环境对应的正确值 - 验证
eb:From/eb:PartyId和eb:To/eb:PartyId:测试环境中From应为你的机构ID,To应为Sabre测试系统的官方ID,确保两者正确无误 - 确认请求端点地址:SessionCreateRQ的测试端点与生产端点不同,需确保请求URL对应当前使用的环境
- 跳过SessionCreateRQ步骤:既然已生成无会话令牌,可直接在请求头中携带该令牌调用接口,无需再创建传统会话——无会话令牌已具备大部分接口的访问权限
内容的提问来源于stack exchange,提问作者Solv_it_kas
相关产品推荐
相关产品推荐

